CVE-2017-10244: Medium severity oracle application object library vulnerability
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10244?
CVE-2017-10244 is classified as an easily exploitable vulnerability that allows unauthenticated attackers to gain unauthorized access via HTTP.
How do I fix CVE-2017-10244?
To fix CVE-2017-10244, apply the latest security patches provided by Oracle for affected versions of the Oracle Application Object Library.
Which versions of Oracle E-Business Suite are affected by CVE-2017-10244?
CVE-2017-10244 affects Oracle E-Business Suite versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
Can CVE-2017-10244 be exploited remotely?
Yes, CVE-2017-10244 can be exploited remotely by an unauthenticated attacker with network access.
What component of Oracle E-Business Suite does CVE-2017-10244 affect?
CVE-2017-10244 affects the Attachments component of the Oracle Application Object Library.